6 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
6.6 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
31.8%
This is a stored cross-site scripting (XSS) vulnerability in an ASM violation viewed in the Configuration utility. In the worst case, an attacker can store a CSRF, which results in code execution as the admin user. (CVE-2019-6607)
The user levels that can store this attack are ASM Administrator, Resource Administrator, and Administrator. The ASM Administrator cannot access the Advanced Shell, but can use this flaw to store an attack that will execute shell commands when an admin with Advanced Shell access browses to the particular BIG-IP ASM Configuration utility page hosting the exploit code. While the stored CSRF is possible in non-appliance and appliance mode systems, the execution of shell commands is not possible if the system is configured in appliance mode because there is no shell available.
Impact
An attacker can inject a malicious script into the BIG-IP ASM Configuration utility. Additionally, an attacker can trick a BIG-IP ASM Configuration utility user into executing malicious code.
#
# (C) Tenable Network Security, Inc.
#
# The descriptive text and package checks in this plugin were
# extracted from F5 Networks BIG-IP Solution K14812883.
#
# The text description of this plugin is (C) F5 Networks.
#
include('compat.inc');
if (description)
{
script_id(123030);
script_version("1.6");
script_set_attribute(attribute:"plugin_modification_date", value:"2023/11/02");
script_cve_id("CVE-2019-6607");
script_name(english:"F5 Networks BIG-IP : BIG-IP ASM XSS vulnerability (K14812883)");
script_set_attribute(attribute:"synopsis", value:
"The remote device is missing a vendor-supplied security patch.");
script_set_attribute(attribute:"description", value:
"This is a stored cross-site scripting (XSS) vulnerability in an ASM
violation viewed in the Configuration utility. In the worst case, an
attacker can store a CSRF, which results in code execution as the
admin user. (CVE-2019-6607)
The user levels that can store this attack are ASM Administrator,
Resource Administrator, and Administrator. The ASM Administrator
cannot access the Advanced Shell, but can use this flaw to store an
attack that will execute shell commands when an admin with Advanced
Shell access browses to the particular BIG-IP ASM Configuration
utility page hosting the exploit code. While the stored CSRF is
possible in non-appliance and appliance mode systems, the execution of
shell commands is not possible if the system is configured in
appliance mode because there is no shell available.
Impact
An attacker can inject a malicious script into the BIG-IP ASM
Configuration utility. Additionally, an attacker can trick a BIG-IP
ASM Configuration utility user into executing malicious code.");
script_set_attribute(attribute:"see_also", value:"https://my.f5.com/manage/s/article/K14812883");
script_set_attribute(attribute:"solution", value:
"Upgrade to one of the non-vulnerable versions listed in the F5 Solution K14812883.");
script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:P");
script_set_cvss_temporal_vector("CVSS2#E:U/RL:OF/RC:C");
script_set_cvss3_base_vector("CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H");
script_set_cvss3_temporal_vector("CVSS:3.0/E:U/RL:O/RC:C");
script_set_attribute(attribute:"cvss_score_source", value:"CVE-2019-6607");
script_set_attribute(attribute:"exploitability_ease", value:"No known exploits are available");
script_set_attribute(attribute:"vuln_publication_date", value:"2019/03/28");
script_set_attribute(attribute:"patch_publication_date", value:"2019/03/21");
script_set_attribute(attribute:"plugin_publication_date", value:"2019/03/25");
script_set_attribute(attribute:"plugin_type", value:"local");
script_set_attribute(attribute:"cpe", value:"cpe:/a:f5:big-ip_application_security_manager");
script_set_attribute(attribute:"cpe", value:"cpe:/h:f5:big-ip");
script_set_attribute(attribute:"generated_plugin", value:"current");
script_end_attributes();
script_category(ACT_GATHER_INFO);
script_family(english:"F5 Networks Local Security Checks");
script_copyright(english:"This script is Copyright (C) 2019-2023 and is owned by Tenable, Inc. or an Affiliate thereof.");
script_dependencies("f5_bigip_detect.nbin");
script_require_keys("Host/local_checks_enabled", "Host/BIG-IP/hotfix", "Host/BIG-IP/modules", "Host/BIG-IP/version");
exit(0);
}
include('f5_func.inc');
if ( ! get_kb_item('Host/local_checks_enabled') ) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
var version = get_kb_item('Host/BIG-IP/version');
if ( ! version ) audit(AUDIT_OS_NOT, 'F5 Networks BIG-IP');
if ( isnull(get_kb_item('Host/BIG-IP/hotfix')) ) audit(AUDIT_KB_MISSING, 'Host/BIG-IP/hotfix');
if ( ! get_kb_item('Host/BIG-IP/modules') ) audit(AUDIT_KB_MISSING, 'Host/BIG-IP/modules');
var sol = 'K14812883';
var vmatrix = {
'ASM': {
'affected': [
'14.0.0-14.0.0.2','13.0.0-13.1.1.3','12.1.0-12.1.3','11.6.1-11.6.3','11.5.1-11.5.8'
],
'unaffected': [
'14.1.0','14.0.0.3','13.1.1.4','12.1.4','11.6.4','11.5.9'
],
}
};
if (bigip_is_affected(vmatrix:vmatrix, sol:sol))
{
set_kb_item(name:'www/0/XSS', value:TRUE);
var extra = NULL;
if (report_verbosity > 0) extra = bigip_report_get();
security_report_v4(
port : 0,
severity : SECURITY_WARNING,
extra : extra
);
}
else
{
var tested = bigip_get_tested_modules();
var audit_extra = 'For BIG-IP module(s) ' + tested + ',';
if (tested) audit(AUDIT_INST_VER_NOT_VULN, audit_extra, version);
else audit(AUDIT_HOST_NOT, 'running the affected module ASM');
}
Vendor | Product | Version | CPE |
---|---|---|---|
f5 | big-ip_application_security_manager | cpe:/a:f5:big-ip_application_security_manager | |
f5 | big-ip | cpe:/h:f5:big-ip |
6 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
6.6 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
31.8%